Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Spoof 127.0.0.1 AND get a response. Possible?
From: Benedikt Stockebrand <benedikt @ devnull . ruhr . de>
Date: 19 Feb 1997 15:39:36 +0100
To: PaLaN <palan @ dataprep . com . my>
Cc: "Frank O'Dwyer" <frank . odwyer @ sse . ie>, firewalls @ GreatCircle . COM
In-reply-to: PaLaN's message of Wed, 19 Feb 1997 10:38:16 -0800
References: <199702191838 . KAA09995 @ snet>

PaLaN <palan @
 dataprep .
 com .
 my> writes:

> As far as I know, 127.0.0.1 is your local/internal loopback address which
> set on your machine.

Correct.

> A packet sent out from your machine to destination
> 127.0.0.1 will not get anywhere cuz, but to your machine itself. 


> None of the
> routers will route a packet destine to 127.0.0.1 cuz its not a valid
> routable route.

What about source routing?

As long as there are still entries in the source route list you don't
have 127.0.0.1 in the destination header field but the next
intermediate address from the source route list.  Unless routers
explicitly look at the source route list they will happily send it to
that address.  Only when it arrives at the last address in that list
will the destination header field be set to 127.0.0.1, which is always
(well, effectively always) the loopback address of the host it is
currently at, i.e. the last address in the source route list.  See
Stevens, TCP/IP Illustrated Vol.1, p.104--109 for details.

> IMHO, I beleive, even by creating source route, you won't
> able to sent packet to 127.0.0.1 to other machines cuz it will confuse the
> routing table and you might end up in big mess. 

Hmm, what have routing tables to do with this?  This isn't an ICMP
Redirect request.


    Ben

-- 
Ben(edikt)? Stockebrand    Runaway ping.de Admin---Never Ever Trust Old Friends
My name and email address are not to be added to any list used for advertising
purposes.  Any sender of unsolicited advertisement e-mail to this address im-
plicitly agrees to pay a DM 500 fee to the recipient for proofreading services.


Follow-Ups:
References:
Indexed By Date Previous: Re: How to configure two network interface into a same subnet?
From: Ruben Sajnovetzky <ruben @ is . com . ar>
Next: Re: Spoof 127.0.0.1 AND get a response. Possible?
From: Benedikt Stockebrand <benedikt @ devnull . ruhr . de>
Indexed By Thread Previous: Re: Spoof 127.0.0.1 AND get a response. Possible?
From: PaLaN <palan @ dataprep . com . my>
Next: Re: Spoof 127.0.0.1 AND get a response. Possible?
From: Les Carleton <les @ tracker . demon . co . uk>

Google
 
Search Internet Search www.greatcircle.com